CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

History

21 Nov 2024, 00:31

Type Values Removed Values Added
References () http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html - Broken Link () http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html - Broken Link
References () http://osvdb.org/36086 - Broken Link () http://osvdb.org/36086 - Broken Link
References () http://secunia.com/advisories/25306 - Third Party Advisory () http://secunia.com/advisories/25306 - Third Party Advisory
References () http://secunia.com/advisories/26102 - Third Party Advisory () http://secunia.com/advisories/26102 - Third Party Advisory
References () http://secunia.com/advisories/26895 - Third Party Advisory () http://secunia.com/advisories/26895 - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 - Third Party Advisory () http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 - Third Party Advisory
References () http://www.novell.com/linux/security/advisories/2007_15_sr.html - Broken Link () http://www.novell.com/linux/security/advisories/2007_15_sr.html - Broken Link
References () http://www.ubuntu.com/usn/usn-485-1 - Third Party Advisory () http://www.ubuntu.com/usn/usn-485-1 - Third Party Advisory
References () http://www.vupen.com/english/advisories/2007/1839 - Third Party Advisory () http://www.vupen.com/english/advisories/2007/1839 - Third Party Advisory

16 Aug 2024, 21:15

Type Values Removed Values Added
Summary (en) The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. (en) The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

Information

Published : 2007-05-16 22:30

Updated : 2024-11-21 00:31


NVD link : CVE-2007-2728

Mitre link : CVE-2007-2728

CVE.ORG link : CVE-2007-2728


JSON object : View

Products Affected

php

  • php

canonical

  • ubuntu_linux